diff --git a/REVIEWED.md b/REVIEWED.md index 0370962..8b03ed5 100644 --- a/REVIEWED.md +++ b/REVIEWED.md @@ -3358,4 +3358,95 @@ caught by a second instrument, not by review.** 5. ⚠ **The assertion-versus-file gap** (§6). `source_lacks`/`source_has` assemble the **assertion's** needle from parts; nothing stops a comment elsewhere in the file planting a contiguous copy. Demonstrated in this sitting, caught only by mutation. **The repaired mechanism is not yet whole**, and §6 declares it verified. 6. **The render-volume hypothesis**, first to test, plausibility flagged as the hazard. -**For a reader in a month, two things.** **The pile-up was never evidence about the cap** — it was evidence about a condition nobody has named. **And the field that would have survived deletion is one opaque integer**, content-free by construction, which did not exist because nobody had asked the question this sitting's instrument just asked. \ No newline at end of file +**For a reader in a month, two things.** **The pile-up was never evidence about the cap** — it was evidence about a condition nobody has named. **And the field that would have survived deletion is one opaque integer**, content-free by construction, which did not exist because nobody had asked the question this sitting's instrument just asked. + +## REVIEWED-138 — PENDING-168 — The count in both units: four instances, seven occurrences (or eleven) +**Date:** 2026-09-10 +**Decision:** AUTHORIZED as to the count. **The unit is declared before the number, and both units are declared.** PENDING-168's doctrine stands at the +strength stated. + +**Ruled by:** steward — the unit is the steward's per REVIEWED-137 §7. +**Drafted by:** executor, at the steward's instruction. The count of instance two's fourth occurrence is the steward's act; the executor declined it and +says so below. +**Authorized by:** steward, 2026-09-10. + +**THE UNIT, FIRST.** The count is stated in two units because the doctrine makes two claims with different denominators, and one number cannot carry both. +Neither figure is to be quoted without its unit. + +- **Named instances: FOUR.** Unit = a distinct governed condition that relied on remembering and was broken. This is the denominator for the claim *a +condition that can only be honoured by remembering will be broken*. +- **Occurrences: SEVEN — or ELEVEN under a per-control reading of instance four.** Unit = a single breach event. This is the denominator for the claim that +the breach recurs, including under active watch. + +**The seven, composed, so the arithmetic is auditable rather than asserted:** + +| instance | occurrences | +|---|---| +| the staleness case written inside the section naming the staleness pattern | 1 | +| the self-planted needle | **4** | +| REVIEWED-128 condition 3 read for content, 2 h 33 min 24 s after receipt | 1 | +| five hook-allowlist controls registered after the tally that would have reported their failure | 1 — **or 5** | +| **total** | **7 — or 11** | + +The four occurrences of instance two: written twice while watching for it (2026-08-27); `tarbuckle-seam.py`'s positive-form control, filed as PENDING-180; +and the comment in PENDING-180 ADDENDUM 1's own repair, which re-planted the needle inside the sentence explaining it. **The executor declined to count the +fourth, correctly — the drafting hand choosing the unit that suits its number is the move the deferral exists to block. The steward counts it.** It is the +third written by a party actively watching for the shape, and on the doctrine's own terms it is the strongest datum the item holds. + +⚠ **ONE UNIT IS INHERITED, NOT DERIVED, AND IS MARKED AS SUCH.** Instance four is counted as **one** occurrence though it names five controls. That reading +comes from PENDING-180's stated base of five occurrences and is adopted here without re-derivation. **This is why the figure is written as "seven, or eleven +under a per-control reading" wherever it appears** — the range is inseparable from the number, because a bare "seven" will be quoted and a caveat will not +travel with it. **The named-instance figure is four under either reading.** + +⚠ **THE DETECTOR'S UNIT IS NOT THE CLAIM'S UNIT, and this entry is the occasion to say so.** The deferred decision `pending-168-count-unit-declared` fires +on the literal `— PENDING-168 —` appearing in REVIEWED.md. That detects **that a ruling was placed on PENDING-168** — not **that the count unit was +declared**. It is correct today only because this entry does both. Since PENDING-168 stays open on the remedy, a later ruling on that remedy would fire the +same needle and report a declaration that had not occurred. **The trigger is a header string standing in for a declaration; it is the same substitution the +item counts.** + +**Two corrections land with this ruling and are not severable from it:** +1. PENDING-168's summary states *"care failed in seven hours."* The interval, measured from receipt, is **2 h 33 min 24 s** (REVIEWED-136). The doctrine's +*"hours, not weeks"* **tightens**; nothing in it weakens. +2. PENDING-180 and its ADDENDUM 1 are part of the evidence base being ruled on, not later commentary on it. +**PENDING-180 is DISCHARGED.** Its (c) census → (b) `source_has()` → (a) repair were executed in that order and the repair is mutation-verified. Its +deferred decision `pending-168-count-unit-declared` is satisfied by this entry. + +**WHAT THIS RULING DOES NOT SETTLE, stated so it is not read as broader than it is.** PENDING-168's structural remedy — **(a) write-only until a date** or +**(b) encrypted at rest to a steward-held key** — is **NOT ruled here and remains open**, as does the question of whether it should be built by the party it +constrains. This entry settles the count and its unit. **The item stays open on the remedy.** + +**If AUTHORIZED:** Proceed. Tag any commit touching the count with REVIEWED-138. A future citation of this doctrine's evidence base must carry its unit +**and its range**; a count stated without them is not to be read as established. + +The errata entry. Filed standalone rather than as an amendment to either ruling: it corrects citations in two entries, so keying it to one misfiles the +other. Re-key it if you'd rather it hang off 136. + +## REVIEWED-139 — ERRATA — Two line citations in placed rulings do not hold, and one never did +**Date:** 2026-09-10 +**Decision:** RECORDED. The citations below are corrected **by this entry joining the record, not by editing the entries that carry them.** No in-place +revision has been made to REVIEWED-136 or REVIEWED-137. + +**Ruled by:** jurist (Claude.app), on a trace run by the executor with explicit argv and reported with its failure mode. +**Authorized by:** steward, 2026-09-10. + +- **REVIEWED.md:2993** (REVIEWED-136) cites `tarbuckle-wrap.py:236` + — the control asserting 12 words are rejected. + It is at **`:256`**. Moved by **`7948c09`**, 2026-09-10, by the executor. +- **REVIEWED.md:3104** (REVIEWED-137) cites `tarbuckle-mumble.py:123` + — `log_rejection()` opening the log in append mode. + It is at **`:139`**. Moved by **`3d45e3a`**, 2026-09-09. + +⚠ **THE SECOND CITATION WAS STALE ON THE DAY IT WAS WRITTEN.** The append-mode open sat at `:123` from `b95ee73` (2026-08-25) through `97a0cb3`, and moved +to `:139` at **`3d45e3a`** — the condition-G commit REVIEWED-136 itself ordered. REVIEWED-137 was placed at `3d340f6`, **after** it. **A ruling cited a line +invalidated by the very commit it was ruling on, the same evening.** This is not decay over time; it is a citation that never held. + +**Why this is recorded rather than repaired.** A placed ruling is amended by a recorded act. Correcting a number inside a placed entry would leave no trace +that the entry had ever been wrong, and the register would then hold a citation that looks as though it had always been right — which is the failure the +register-integrity check was built for (2026-08-07, REVIEWED-87 overwritten by its own amendment). + +**The general finding, carried to PENDING-183 item 11, which changes from observational to load-bearing:** the register cites code by line, lines move, and +**nothing re-checks any citation.** Two placed rulings are wrong today; `tarbuckle-seam.py` moved twice in two days. ⚠ **Recommended and NOT authorized +here: anchor register citations to symbols or content rather than line numbers** — the reasoning that makes `source_has()` assemble its needle from parts. A +line number in a placed ruling is a claim with a half-life measured in days. + +**If AUTHORIZED:** Proceed. Future citations of code in this register carry a symbol or a quoted fragment; a bare `file:line` is to be read as provisional. \ No newline at end of file